Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.38%—IBM Sterling Connect Direct WEB Services19/1/202517/6/2026
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used in further attacks against the system.
ModificadaAlta (7.5)4.7%—Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+1614/1/202530/6/2026
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
ModificadaAlta (7.5)2.3%—Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+1414/1/202530/6/2026
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification…
ModificadaAlta (7.5)8.8%💥 PoCSamba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+1814/1/202521/9/2026
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
AnalizadaAlta (7.5)0.51%—Restful WEB Services Project Restful WEB Services9/1/202517/6/2026
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.
AnalizadaMedia (5.4)0.29%—Cisco Crosswork Network ControllerCisco Common Services Platform Collector8/1/202517/6/2026
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the…
AnalizadaMedia (5.4)0.29%—Cisco Crosswork Network ControllerCisco Common Services Platform Collector8/1/202517/6/2026
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the…
AnalizadaMedia (5.4)0.37%—Cisco Crosswork Network ControllerCisco Common Services Platform Collector8/1/202517/6/2026
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the…
AnalizadaCrítica (9.8)0.55%—Apple Smart Card Services8/1/202517/6/2026
This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.
AnalizadaMedia (5.1)0.68%—Acetech Home Clean Services Management System7/1/202517/6/2026
A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /public_html/admin/process.php. The manipulation of the argument type/length/business leads to sql injection. The attack can be…
AplazadaAlta (7.1)0.26%—Irshad A Khan Services Updates FOR CustomersAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0.
ModificadaAlta (8.6)0.59%—Amazon WEB Services Redshift Java Database Connectivity Driver24/12/202417/6/2026
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
AplazadaMedia (6.5)1.3%💥 PoCWp-base Booking OF Appointments Services AND EventsAI21/12/202417/6/2026
The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
AplazadaAlta (8.5)0.49%—Ydesignservices YDS Support Ticket SystemAI18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YDS Support Ticket System yds-support-ticket-system allows SQL Injection.This issue affects YDS Support Ticket System: from n/a through <= 1.0.
AplazadaMedia (6.5)0.39%—Digital Operation Services WifiburadaAI17/12/202417/6/2026
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.
AplazadaMedia (4.3)0.40%—Digital Operation Services WifiburadaAI17/12/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5.
AnalizadaAlta (7.2)23%—Ivanti Cloud Services Appliance10/12/202417/6/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AnalizadaAlta (7.2)7.7%—Ivanti Cloud Services Appliance10/12/202417/6/2026
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaCrítica (9.8)4.9%—Ivanti Cloud Services Appliance10/12/202417/6/2026
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
AplazadaAlta (7.1)0.37%—Roninwp FAT Services BookingAI9/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Services Booking fat-services-booking allows Stored XSS.This issue affects FAT Services Booking: from n/a through <= 5.6.
AplazadaCrítica (9.3)0.44%—Roninwp FAT Services BookingAI5/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking.This issue affects FAT Services Booking: from n/a through <= 5.6.
AplazadaAlta (7.1)0.30%—Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI3/12/202417/6/2026
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01.
AplazadaAlta (7.1)0.33%—Dhrubok Infotech Services LTD Woocommerce Price AlertAI2/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhrubok Infotech Services Ltd. WooCommerce Price Alert price-alert-woocommerce allows Reflected XSS.This issue affects WooCommerce Price Alert: from n/a through <= 1.0.4.
AplazadaAlta (8.4)0.49%—B&R Mapp CockpitAIB&R Mapp ViewAIB&R Mapp ServicesAIB&R Mapp MotionAI+12/12/202417/6/2026
An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based…
AplazadaMedia (6.5)1.2%—Keycloak-servicesAI25/11/202421/9/2026
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.